yagames-mcp
An MCP server for Yandex Games: catalog search with no auth, plus draft management, build uploads and publishing through the developer console
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Can publish and update games on behalf of the developer account
- The Session_id and CSRF token grant full console access rather than scoped rights
- Authentication relies on unofficial cookie access rather than a platform-issued key
Install
Manual install
npm install
npm run buildInstall dependencies and build the project.
This is third-party code. Review the repository files before installing.
What it does
The server offers two tool layers. Public tools need no authentication: searching games by keyword, listing popular games filtered by category, and listing 27 genres, all read from the yandex.ru/games catalog page. Authenticated tools work through the developer console: creating and updating a game draft, uploading a ZIP build as a new version, submitting for moderation, publishing a game that passed review, and checking status or listing every game on the account. Authentication is not an official API key but a Session_id cookie and an X-CSRF-Token header, copied manually from browser DevTools after logging into the console.
Who it is for. For HTML5 game developers who publish to the Yandex Games catalog and want to automate build uploads.
Good fit when
- You want to quickly browse the catalog, popular games or genre list without logging in
- You want to automate uploading a new build and submitting it for moderation from a conversation with an agent
- You run several games on one developer account and need a unified status view
Not a fit when
- You do not want to manually pull the Session_id and CSRF token from DevTools and store them in environment variables
- You need an official API instead of unofficial console-cookie access: the project offers no other way
Example request
Check the moderation status of all my games on Yandex GamesLimitations
Publishing and build uploads work through unofficial developer-console cookie access rather than a documented API key. The Session_id and CSRF token grant full access to the developer account and have no built-in expiry handling in the project; the author explicitly warns not to share them. Public search is built on parsing the catalog page's HTML and can break if it changes.
How to disable. Remove the server from your MCP client config and log out of the Yandex Games console to invalidate the Session_id.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| YAGAMES_SESSION_COOKIE secret | The Session_id cookie value from the developer console, needed for game management |
| YAGAMES_CSRF_TOKEN secret | The X-CSRF-Token header value from the developer console |
Security check
- Can publish and update games on behalf of the developer account
- The Session_id and CSRF token grant full console access rather than scoped rights
- Authentication relies on unofficial cookie access rather than a platform-issued key
README in short
The English README splits tools into public, no-auth ones and authenticated console ones. It gives a tool table, instructions for pulling the Session_id and CSRF token from DevTools with an explicit warning not to share or commit them, config examples for opencode and Claude Desktop, an architecture diagram separating the catalog client from the console client, a list of console REST endpoints, and background on the Yandex Games platform: over 2,000 games, 27 genre categories, ad-based monetization. MIT license.
FAQ
Does game search need authentication?
No, the yagames-search, yagames-popular and yagames-categories tools are public and need no keys or cookies.
Where do I get the Session_id and CSRF token?
From browser DevTools after logging into games.yandex.ru/console: the Session_id cookie under the Application tab, and the X-CSRF-Token header on a POST request to /console/api/application under the Network tab.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything